Security Lab.Secure by design, with the evidence regulators ask for.
We build security into delivery: threat models before code, secure review on every pull request, and dependency and secrets scanning in the pipeline. For independent assurance, penetration testing and its sign-off are carried out by accredited CREST partners.
Build · Run · 24/7
01What we build
What the Security Lab builds.
Archetypes, named by what they do. Every engagement also carries the standards we apply in every lab.
- 01
Secure development lifecycles
Threat modelling, review and scanning built into the way your teams already ship.
- 02
Threat models
Structured models of what could go wrong in a system, kept current as the architecture changes.
- 03
Secure code review
Automated and human review on every pull request, with findings tracked to closure.
- 04
DORA and FCA resilience evidence
Mapping, scenario testing and documentation that demonstrate operational resilience, produced as part of delivery.
- 05
Certification readiness
Gap analysis and remediation so you arrive at Cyber Essentials Plus or ISO 27001 assessment prepared.
- 06
Hardening live systems
Headers, TLS, identity, secrets and dependencies brought up to standard on platforms already in production.
02Services
Services and deliverables.
Concrete scopes with named outputs, so you know what you will hold at the end of each stage.
Security review
Architecture and code review of an existing system, with prioritised findings and the fixes to close them.
- Threat model
- Findings report
- Remediation pull requests
Secure delivery
Security review, dependency scanning and secrets detection added as gates in your pipeline.
- Pipeline security gates
- Dependency and secrets scanning
- Secure coding guide
Resilience and compliance evidence
DORA, FCA SYSC 15A, Cyber Essentials Plus and ISO 27001 readiness work.
- Gap analysis
- Evidence pack
- Remediation plan
Partner-attested penetration testing
Scoping, coordination and remediation around tests performed by accredited CREST partners.
- Test scope
- Partner report
- Retest of fixes
03Live tool: Security headers check
Check your headers.
Review the HTTP security headers a site sends and generate a hardened policy to copy. A useful first look, not a penetration test.
04Lab standard
The A* standard for this lab.
On top of fixed-price discovery, a named lead, code you own, test gates, observability, written decisions and an SLA-backed run retainer, this lab adds:
- 01
A threat model for every significant system
Written before the build starts and updated whenever the architecture changes.
- 02
Secure code review on every pull request
Automated security review runs on each pull request through the Claude Code GitHub Action, and an engineer reviews anything it flags.
- 03
Dependency and secrets scanning
Vulnerable packages and leaked credentials are caught in the pipeline, before they ship.
- 04
Evidence as a by-product
Reviews, scans and decisions are logged and retained, so audit evidence exists before anyone asks for it.
05Human sign-off
Where people sign off.
Independent assurance has to be independent. We prepare, coordinate and fix; accredited specialists test and attest.
- Penetration test sign-offPenetration tests and their sign-off are performed by accredited CREST partners, independent of the team that built the system.
- CertificationCyber Essentials Plus and ISO 27001 certificates are issued by accredited certification bodies. We prepare you; they assess.
- Risk acceptanceAccepting a residual risk is a decision for your accountable executive, recorded in writing.
Penetration test sign-off is provided through accredited CREST partners. Aurion Labs does not issue security certifications and does not claim any on your behalf.
06FAQ
Questions, answered.
Do you carry out penetration tests yourselves?
No. We scope, coordinate and fix; the testing and sign-off are carried out by accredited CREST partners so the assurance is independent.
Can you help us achieve Cyber Essentials Plus or ISO 27001?
We prepare you with gap analysis, remediation and evidence. The certificate itself is awarded by an accredited body.
How does AI-assisted code stay secure?
Every change passes the same gates as hand-written code: automated security review, dependency and secrets scanning, tests and review by an engineer before it merges.
What does DORA evidence involve?
Mapping critical services and the systems and third parties they depend on, testing failure scenarios and recording the results in a form that supports DORA and FCA operational resilience obligations. Your firm owns the conclusions.
08Contact
Show us what needs protecting.
Your first call is with an engineer from the Security Lab, not a sales script. Bring the system, the deadline and the constraints.
hello@aurionlabs.io